Showing posts with label Virus/Malware. Show all posts
Showing posts with label Virus/Malware. Show all posts

vml.exe aka XP Internet Security 2012

Here we have a FAKE internet security tool called XP Internet Security 2012 (which also goes by different aliases), which infected a Windows XP machine causing it to become unable to run .exe file types. This creates a serious issue when most every application you want to run – or need to run to clean up the Virus/Malware – will be an .exe file type. Below I have listed what I did to clean the infected system.

The “shield” that looks similar to the Windows Update and some antivirus shields, was located in the task manager near the clock to the bottom right of the screen. This was even after the user had run Malwarebytes and thought the Virus/Malware had already been completely removed.

REMEMBER: If you believe that your computer is infected, not only do you need to run a full system scan with your antivirus software – and/or Malwarebytes – you also need to perform a search of your (a) hard drive and (b) registry for other Virus/Malware that may not have been detected.

Virus/Malware name: vml.exe

Hard Drive:
C:\Documents and Settings\%username%\Local Settings
C:\Windows\Prefetch (as VML.EXE-074511AD.pf)

Registry values .exe and exefile were corrupt:
HKEY_CLASSES_ROOT
This caused the computer to no longer be able to execute .exe file types, even after the Virus/Malware had been removed.

Click here or review Microsoft’s article to see what actions I performed to remedy the infection.

ms0cfg32.exe

Here we have more Virus/Malware parading around on a computer within the Windows XP operating system and its registry. Again, Malwarebytes’ Anti-Malware located and either deleted or quarantined the infections.

IPH.Trojan.Blueinit
File: desktopwisvcs.dll
Location:
C:\Documents and Settings\%username%\Local Settings\Application Data\odbcmouseport\
Registry: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\DesktopWISvcs


Exploit.Drop.CFG
File: ms0cfg32.exe
Location: C:\Documents and Settings\%username%\Local Settings\Temp\


Hijack.Shell.Gen
Registry: HKEY_CURRENT_USER\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogin\Shell


Always remember to search the registry and hard drive for other possible Virus/Malware related infections; especially when you find one on your computer at any time.


Click here: to see how to run a full search of your hard drive
Click here: to see how to run a full search of your registry

desktopwisvcs.dll

Here we have more Virus/Malware parading around on a computer within the Windows XP operating system and its registry. Again, Malwarebytes’ Anti-Malware located and either deleted or quarantined the infections.

IPH.Trojan.Blueinit
File: desktopwisvcs.dll
Location:
C:\Documents and Settings\%username%\Local Settings\Application Data\odbcmouseport\
Registry: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\DesktopWISvcs


Exploit.Drop.CFG
File: ms0cfg32.exe
Location: C:\Documents and Settings\%username%\Local Settings\Temp\


Hijack.Shell.Gen
Registry: HKEY_CURRENT_USER\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogin\Shell


Always remember to search the registry and hard drive for other possible Virus/Malware related infections; especially when you find one on your computer at any time.


Click here: to see how to run a full search of your hard drive
Click here: to see how to run a full search of your registry

enkai.exe

Here we have a Rootkit.0Access.XGen Virus/Malware attack, which kept sending out requests to websites (most likely to continue the malicious attacks on the host computer). We made a change in the TrendMicro settings to now block automatic access of certain websites, so we are being notified of Unauthorized URL’s.

Virus/Malware: enkai.exe

Hard Drive Location:
C:\Documents and Settings\%username%\Application Data\Yvqouw
Remember to always look for bogus folders in the Application Data directory. Yvgouw is definitely bogus.

There was also a variant bogus folder with the files xono.oco and xono.tmp:
C:\Documents and Settings\%username%\Application Data\Ungue

Also remember to take this time to clean out:
C:\Documents and Settings\%username%\Local Settings\Temp

Registry Location:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

The blocked websites:
http://nahwisohch.ru/bin/xxl.bin
http://munaeghohz.ru/bin/xxl.bin
http://jupaizeuph.ru/bin/xxl.bin

kb00045929.exe

Today we came across another Trojan.Agent according to Malwarebytes Anti-Malware.

Filename: kb00045929.exe

The filename and entry were located in the following of a Windows 7 computer.

Hard drive: C:\Users\%username%\AppData\Roaming\

Registry: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Please note that although we are posting these by filename, the filename may be merely variants and randomly generated by the actual Virus/Malware. For this reason, when you do detect Virus/Malware on your computer, you should also take a moment to look in the same locations for other oddly named files/folders such as those named with only a few numbers or mixed numbers/characters.

While you are viewing the C:\Users\%username%\AppData\Roaming\ you should also check:
· C:\Users\%username%\AppData\Local\
· C:\Users\%username%\AppData\Local\Temp (delete items you can in here)
· C:\Users\%username%\AppData\Roaming\LocalLow

** %username% ** replace with the actual username(s) folders within the C:\Users directory on the specific computer you are working on, as this will change with each computer by user.

To do the above, you must first enable the option to view hidden files, if not already enabled. Click here to see how to do that.

Here are the similar folders to check in Windows XP.
· C:\Documents and Settings\%username%\Application Data
· C:\Documents and Settings\%username%\Local Settings
· C:\Documents and Settings\%username%\Local Settings\Temp (delete items you can in here)

21D.tmp

We recently had a Virus/Malware attack on our network by the names of TROJ_GEN.R28C7KB and TROJ_KAZY.SMO which were infecting the bogus files named 018.exe and 21D.tmp within C:\Program Files\LP\E650\ on a Windows XP machine.

TrendMicro found and cleaned three (3) in which these same files were located on the hard drive. Malwarebytes Anti-Malware also removed five (5) which TrendMicro did not find. Malwarebytes is free, but TrendMicro also has a free antivirus (here) which can be run from a web browser.

Even so, we had to manual search the registry and hard drive to find and delete a few more instances of similar files with number and mixed number/character names elsewhere on the hard drive. Sorry, did not manage to note these before they were removed.

Click here: to see how to run a full search of your hard drive
Click here: to see how to run a full search of your registry

018.exe

We recently had a Virus/Malware attack on our network by the names of TROJ_GEN.R28C7KB and TROJ_KAZY.SMO which were infecting the bogus files named 018.exe and 21D.tmp within C:\Program Files\LP\E650\ on a Windows XP machine.

TrendMicro found and cleaned three (3) in which these same files were located on the hard drive. Malwarebytes Anti-Malware also removed five (5) which TrendMicro did not find. Malwarebytes is free, but TrendMicro also has a free antivirus (here) which can be run from a web browser.

Even so, we had to manual search the registry and hard drive to find and delete a few more instances of similar files with number and mixed number/character names elsewhere on the hard drive. Sorry, did not manage to note these before they were removed.

Click here: to see how to run a full search of your hard drive
Click here: to see how to run a full search of your registry